Security

Security you can describe in one paragraph.

Encryption in transit and at rest. Per-workspace isolation. We never train models on your data, and we never sell it. Audit logs for sensitive admin actions. GDPR-aligned. SOC 2 Type II in progress.

Encryption everywhere

All data is encrypted in transit (TLS 1.2+) and at rest (AES-256). Database backups are encrypted with separate keys.

Per-workspace isolation

Workspaces are logically isolated. The AI assistant can only read data inside the workspace it was invoked from.

Your data is your data

We never sell Customer Data and never use it to train AI models. Export anytime via Settings → Export.

Audit logs

Sensitive admin actions (member invites, role changes, billing) are logged with actor, timestamp, and IP.

Auth & access

Email + magic link by default. Google SSO available. SAML SSO and SCIM on the roadmap (Q3 2026).

Compliance

GDPR-aligned data handling. SOC 2 Type II in progress (target Q4 2026). DPA available on request.